peter bassill · operator
$ cve search RSS KEV calendar

CVE Explorer.

Every published CVE, ranked the way you should actually patch: KEV first, then anything with a public exploit or an EPSS above ten per cent, then down by CVSS.

398,529 CVEs 1,726 on KEV 17,265 EPSS ≥ 10% 25,086 with exploits synced 2026-09-27

36,454 results

CVESummaryPriorityCVSSEPSSPublished
CVE-2025-22224 KEV VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with l… Patch first 9.3 critical 1.6% 2025-03-04
CVE-2026-72529 KEV A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, a… Patch first 9.8 critical 1.5% 2026-08-19
CVE-2026-48027 KEV Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed… Patch first 9.8 critical 1.3% 2026-05-27
CVE-2026-65400 KEV An authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macOS Sonoma… Patch first 9.8 critical 1.2% 2026-08-06
CVE-2025-59374 KEV "UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supp… Patch first 9.8 critical 1.2% 2025-12-17
CVE-2026-45321 KEV On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The… Patch first 9.6 critical 1.1% 2026-05-12
CVE-2026-48172 KEV LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best… Patch first 9.8 critical 1% 2026-05-21
CVE-2026-8452 KEV Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the applianc… Patch first 9.8 critical 1% 2026-06-30
CVE-2026-16812 KEV VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and… Patch first 10.0 critical 1% 2026-07-27
CVE-2026-85102 KEV Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to e… Patch first 9.8 critical 1% 2026-09-09
CVE-2026-8398 KEV A supply chain attack compromised the official installation packages of DAEMON Tools Lite (Windows versions 12.5.0.2421 through 12.5.0.2434), distribu… Patch first 9.8 critical 1% 2026-05-15
CVE-2026-84869 KEV A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host… Patch first 9.9 critical 0.9% 2026-09-08
CVE-2026-93952 KEV VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and… Patch first 10.0 critical 0.9% 2026-09-22
CVE-2026-46817 KEV Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2… Patch first 9.8 critical 0.8% 2026-05-28
CVE-2026-5430 KEV The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to… Patch first 10.0 critical 0.6% 2026-08-06
CVE-2022-42889 EXP Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolati… Patch early 9.8 critical 99.9% 2022-10-13
CVE-2017-12635 EXP Due to differences in the Erlang-based JSON parser and JavaScript-based JSON parser, it is possible in Apache CouchDB before 1.7.0 and 2.x before 2.1.… Patch early 9.8 critical 99.8% 2017-11-14
CVE-2017-8917 EXP SQL injection vulnerability in Joomla! 3.7.x before 3.7.1 allows attackers to execute arbitrary SQL commands via unspecified vectors. Patch early 9.8 critical 99.8% 2017-05-17
CVE-2020-10220 EXP An issue was discovered in rConfig through 3.9.4. The web interface is prone to a SQL injection via the commands.inc.php searchColumn parameter. Patch early 9.8 critical 99.7% 2020-03-07
CVE-2023-27372 EXP SPIP before 4.2.1 allows Remote Code Execution via form values in the public area because serialization is mishandled. The fixed versions are 3.2.18,… Patch early 9.8 critical 99.7% 2023-02-28
CVE-2022-37061 EXP All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are vulnerable to Remote Command Injection. This can be exploited to inject an… Patch early 9.8 critical 99.6% 2022-08-18
CVE-2023-32560 EXP An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code executi… Patch early 9.8 critical 99.4% 2023-08-10
CVE-2025-1974 EXP A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve a… Patch early 9.8 critical 99.4% 2025-03-25
CVE-2017-12542 EXP A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53 was found. Patch early 10.0 critical 99.3% 2018-02-15
CVE-2023-23333 EXP There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions throug… Patch early 9.8 critical 99.3% 2023-02-06
CVE-2025-29927 EXP Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and 1… Patch early 9.1 critical 99.2% 2025-03-21
CVE-2022-24637 EXP Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin… Patch early 9.8 critical 99.1% 2022-03-18
CVE-2020-7209 EXP LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2. Patch early 9.8 critical 98.8% 2020-02-13
CVE-2018-19276 EXP OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitrary command… Patch early 9.8 critical 98.7% 2019-03-21
CVE-2020-15920 EXP There is an OS Command Injection in Mida eFramework through 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (… Patch early 9.8 critical 98.2% 2020-07-24
← previous page 21 of 334 next →

How to read it

Patch the KEV entries first — those are being exploited in the wild right now — then anything with a public exploit or an EPSS above ten per cent, then work down by CVSS in your normal cycle. That order, not raw CVSS, is what keeps you ahead of what is actually being used against people. The data is drawn daily from NVD, FIRST EPSS, CISA KEV and Exploit-DB.

Watch your own stack → and get told only when something that matters to it moves.

→ all tools  ·  exposure  ·  dns  ·  email  ·  headers  ·  tls  ·  ct  ·  cookies  ·  reputation  ·  security.txt